Re: Logging attempted passwords

From: Greg Wooledge (wooledg_at_eeg.ccf.org)
Date: 10/22/04

  • Next message: Bartek Krajnik: "Re: Logging attempted passwords"
    Date: Fri, 22 Oct 2004 08:03:19 -0400
    To: secureshell@securityfocus.com
    
    

    On Fri, Oct 22, 2004 at 02:57:24PM +0900, Derek Martin wrote:
    > David appears to be asking for the PASSWORD the user used on a failed
    > attempt. I'm not 100% positive, but I believe OpenSSH does not
    > provide a mechanism to get the password.

    Logging failed passwords is a Very Bad Idea if you actually *use*
    password authentication.

    Suppose your password is 'Open*SSH-3.9' (without the quotes). But
    that's pretty hard to type on some keyboards with hyperactive Shift
    keys, so maybe you fail by accidentally typing 'OPen*SSH-3.9', and
    that gets logged. Now, someone gets hold of your logs (by whatever
    means). Do you think your password is "safe" any more?


  • Next message: Bartek Krajnik: "Re: Logging attempted passwords"

    Relevant Pages

    • Re: the liver and the brain
      ... You fail to explain why your own verbal ... relative to you (and some of the other presumptuous idiots ... >that I've got something more informed and worth paying attention to ... David, I'm beginning to wonder exactly what the hell you and Glen ...
      (sci.cognitive)
    • Re: seeking
      ... What perturbs you about this post, David? ... It's the whole thread more than the post, but "sloppy ... over-the-hill drinkers" rubs me the wrong way, ... Rarely have we seen a person fail who has thoroughly followed ...
      (soc.motss)
    • Re: Full Office 97 install kills vba
      ... > david beattie wrote: ... >> go to a dead address, and fail. ... >> when installing to prevent those moaning msgboxes, ...
      (microsoft.public.office.setup)
    • Re: Full Office 97 install kills vba
      ... >> david beattie wrote: ... >>> go to a dead address, and fail. ... >>> when installing to prevent those moaning msgboxes, ...
      (microsoft.public.office.setup)
    • Re: HostBased Authentication issues : OpenSSH 3.4p1
      ... I had it working at openssh 3.1 but it seems to fail now. ... >>The client recognizes the server host key and the server tries host ... I have hostbased authentication working using that, ...
      (comp.security.ssh)

  • Quantcast